PT-2025-47583 · Unknown · Phppgadmin
Published
2025-11-17
·
Updated
2025-12-18
·
CVE-2025-60798
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
phpPgAdmin versions 7.13.0 and earlier
Description
phpPgAdmin versions 7.13.0 and earlier contain a SQL injection issue in the display.php file at line 396. The application directly uses user-provided input from the
query parameter in the $ REQUEST array within the browseQuery function without sufficient sanitization. An authenticated attacker can manipulate queries to execute arbitrary SQL commands, potentially compromising the entire database. The vulnerable parameter is query.Recommendations
Versions prior to 7.13.0 are affected.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phppgadmin